CVE-2026-3731 | libssh up to 0.11.3 SFTP Extension Name src/sftp.c sftp_extensions_get_name/sftp_extensions_get_data idx out-of-bounds (libssh-2026-sftp-extensions / EUVD-2026-10234)
A vulnerability, which was classified as problematic, was found in libssh up to 0.11.3. The impacted element is the function sftp_extensions_get_name/sftp_extensions_get_data of the file src/sftp.c of the component SFTP Extension Name Handler. Executing a manipulation of the argument idx can lead to out-of-bounds read.
This vulnerability appears as CVE-2026-3731. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.